216.73.216.6

PDFSIDER Malware - Exploitation of DLL Side-Loading for AV and EDR Evasion

· Published 18/01/2026 18:38 · Modified 19/01/2026 09:30

Export JSON

Essential information

Published
18/01/2026 18:38
Modified
19/01/2026 09:30
Tags
2026-01-18 aes-256-gcm anti-vm apt dll side-loading in-memory backdoor pdf24 creator pdfsider spear-phishing
Related entities
5 observables, 8 techniques (mitre), 1 malware

Description

is a newly identified malware variant that utilizes to deploy a covert backdoor with encrypted command-and-control capabilities. It exploits vulnerabilities in legitimate software like to bypass endpoint detection mechanisms. The malware operates primarily in memory, minimizing disk artifacts, and employs advanced technology to evade sandboxes and analysis labs. features a robust cryptographic implementation using the Botan library for secure communications. It gathers system information and provides attackers with an interactive, hidden command shell for remote execution. The malware's characteristics align with tradecraft, suggesting its use in cyber-espionage operations. Distribution occurs through emails containing ZIP archives with legitimate-looking executables.

External references